What we collect
When you send an inquiry, we collect the name, email address, and trip details you provide so we can respond and plan your journey. Account holders (the travel host and collaborators) also have an authenticated profile used to manage trip listings and the daily destination spotlight.
We do not request or store passport numbers, payment card numbers, or financial account details on this site. Bookings are completed off-platform through the travel agent using a separate, secure credit card authorization process.
How information is protected
Inquiry submissions and trip content are stored in our managed backend with row-level security enabled on every customer-data table. Write access to trip listings and the destination spotlight is restricted to authenticated admin accounts; public visitors can only read the published content shown on this site.
Administrative database functions are scoped to the backend service role only and are not callable by signed-in users or the public. Connections between your browser and our backend use TLS in transit.
Authentication
Sign-in is available to the travel host and authorized collaborators. We use email and password authentication backed by our managed auth provider. Visitors do not need to create an account to browse trips, view the spotlight, or send an inquiry.
Images and storage
Trip and destination spotlight images are served from private storage buckets through time-limited URLs. Uploads and edits to those images are restricted to admins via row-level security policies.
Subprocessors and integrations
We rely on a small set of trusted infrastructure providers to operate the site:
- Hosting, database, authentication, and storage: Lovable Cloud
- Daily destination spotlight content and imagery: Lovable AI Gateway
- Transactional and authentication email delivery: Lovable Emails
We do not sell your information, and we do not share inquiry data with advertising networks.
Cookies and analytics
The site uses only the cookies and local storage required to keep an admin signed in and to remember session state. We do not run third-party advertising trackers on this site.
Data retention and deletion
Inquiry messages are retained for as long as needed to respond and plan your trip. If you would like your inquiry, contact details, or any other personal information we hold deleted, contact us at the address below and we will remove it from our systems.
Security contact
If you believe you have found a security issue, please reach out through the inquiry form on the homepage and mark your message as a security report. We will acknowledge and investigate promptly.
Shared responsibility
Crown & Compass Travel maintains the application, content, and customer-facing controls described here. Underlying platform capabilities — including managed database security, authentication, storage, and email infrastructure — are operated by Lovable Cloud. Travelers are responsible for protecting access to their own email inbox used to receive itineraries and confirmations.